OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Jeev (geonappacbell.net)
Date: Thu Jul 19 2001 - 01:59:50 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    rootbuttmunch:~# ls -l /lib/modules/`uname -r`/modules.dep
    -rw-r--r-- 1 root root 49902 Jun 16 20:26
    /lib/modules/2.2.19/modules.dep
    rootbuttmunch:~# uname -a
    Linux buttmunch 2.2.19 #5 Sat Jun 16 20:13:44 PDT 2001 i686 unknown
    rootbuttmunch:~#
    ^ linux slackware 8.0

    rootthunder:~# ls -l /lib/modules/`uname -r`/modules.dep
    -rw-rw-rw- 1 root root 4327 Jul 12 19:49
    /lib/modules/2.4.5/modules.dep
    rootthunder:~# uname -a
    Linux thunder 2.4.5 #1 SMP Thu Jul 12 19:45:50 MST 2001 i686 unknown
    rootthunder:~#
    ^ linux slackware 8.0

    j

    -----Original Message-----
    From: twiz - Perla Enrico [mailto:twiboiate.it]
    Sent: Tuesday, July 17, 2001 3:43 PM
    To: bugtraqsecurityfocus.com
    Subject: Re: 2.4.x/Slackware Init script vulnerability

    I' ve tested it on Slackware 7.0 with kernel 2.4.5 :
    twisterz:~# uname -r
    2.4.5
    twisterz:~#

    I' ve noticed that , while /var/run/utmp *is* world writable :
    twisterz:~# ls -l /var/run/utmp
    -rw-rw-rw- 1 root root 4608 Jul 17 02:27 /var/run/utmp
    twisterz:~#
    and also /var/run/gpm.pid is -rw-rw-rw-, *but* modules.dep isn' t
    writable

    twisterz:~# ls -l /lib/modules/`uname -r`/modules.dep
    -rw-r--r-- 1 root root 2688 Jul 16 19:36
    /lib/modules/2.4.5/modules.dep
    twisterz:~#

    So it can't be edited, and the exploit can' t work 'cause you can't
    add/change lines to modules.dep.
    I'm going to download Slackware 8.0 and test on it, btw on slak 7.0 keep
    good the possibility of, as you said :

    >
    > And of course with /var/run/utmp writeable, users can delete
    or
    in
    > other ways manipulate their logins as they appear in
    > w/who/finger/getlogin(), etc.
    >

    twiz - twizsuperdotati.net or twiboiate.it - ./twlc